Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Author Yannick Lefebvre

    (@jackdewey)

    That exploit has long been corrected in Link Library. Have you been keeping up with updates? Who is saying that this specific exploit is causing you problems?

    Thread Starter johnaustinny

    (@johnaustinny)

    Yannick, my security team is telling me that the plugin has a vulnerable spot and the link i attached to the previous post was what they sent me. could you explain a little more about the issue at had. Thank You

    Plugin Author Yannick Lefebvre

    (@jackdewey)

    There was previously an SQL injection vulnerability in the search code. This code was revised since to make sure that each search term is a single string.

    Here is the delta between version 5.2.1 where the issue was found and version 5.2.2 where it was corrected.

    http://plugins.trac.wordpress.org/changeset?reponame=&new=438811%40link-library%2Ftrunk&old=436614%40link-library%2Ftrunk

    The fix was approved by the WordPress plugin support team.

    If you security team thinks that this fix is not sufficient, you can have them send me a proposed fix and I will roll it into the plugin.

    Thread Starter johnaustinny

    (@johnaustinny)

    thank you for the help. I will let you know if i they send me any other changes. real quick i have a map program any chance you know of a plugin that links “links” on a page to a point on a map. so if you say you have map on the top of a page and below you have a buch of links. If you click on a link it takes you to a place on the map.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Link Library Being Compromised’ is closed to new replies.